What is CVSS?
Common Vulnerability Scoring System: FIRST's standard 0.0–10.0 score for how severe a vulnerability is, based on how it can be exploited and what it affects.
The base score is computed from a vector of metrics. In CVSS v3.1 they are attack vector, attack complexity, privileges required, user interaction, scope, and the impact on confidentiality, integrity and availability. The qualitative ratings are None (0.0), Low (0.1–3.9), Medium (4.0–6.9), High (7.0–8.9) and Critical (9.0–10.0).
CVSS v4.0 (published in 2023) splits the score into base, threat, environmental and supplemental groups and names results like CVSS-B or CVSS-BT to show which groups were used.
CVSS measures severity, not likelihood: a 9.8 that nobody exploits can matter less than a 7.5 in the KEV catalog. That is why it is usually combined with EPSS and KEV.
Example:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H = network attack, low complexity, no privileges or user action needed, high impact on all three: base score 9.8 (Critical).Sources
Related terms
- EPSSExploit Prediction Scoring System: FIRST's daily estimate of the probability (0 to 1) that a CVE will see exploitation activity in the next 30 days.
- NVDThe National Vulnerability Database run by NIST, which republishes CVE records and adds analysis such as CVSS scores, CWE types and CPE product names.
- CVECommon Vulnerabilities and Exposures: the public ID system for disclosed security flaws, written as CVE-YEAR-NUMBER, for example CVE-2021-44228.